CVE-2026-73434

EUVD-2026-57443
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.39%
Affected Products (NVD)
VendorProductVersion
gstreamergstreamer
𝑥
< 1.28.6
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gst-plugins-good1.0
bookworm
vulnerable
bookworm (security)
vulnerable
forky
1.28.7-1
fixed
sid
1.28.7-1
fixed
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gst-plugins-good1.0
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
gstreamer1-plugins-good
RHEL 8
0:1.16.1-7.el8_10.3
fixed
RHEL 8.4 AUS
0:1.16.1-4.el8_4.2
fixed
RHEL 8.6 AUS
0:1.16.1-4.el8_6.3
fixed
RHEL 8.8 E4S
0:1.16.1-5.el8_8.3
fixed
RHEL 8.8 TUS
0:1.16.1-5.el8_8.3
fixed
RHEL 9
0:1.22.12-7.el9_8.4
fixed
gstreamer1-plugins-good-gtk
RHEL 8
0:1.16.1-7.el8_10.3
fixed
RHEL 8.4 AUS
0:1.16.1-4.el8_4.2
fixed
RHEL 8.6 AUS
0:1.16.1-4.el8_6.3
fixed
RHEL 8.8 E4S
0:1.16.1-5.el8_8.3
fixed
RHEL 8.8 TUS
0:1.16.1-5.el8_8.3
fixed
RHEL 9
0:1.22.12-7.el9_8.4
fixed